New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A successful brute-force attack on a PostgreSQL database exploited a feature that allowed command execution, where the attacker created a superuser role, dropped files to eliminate competition and gain persistence, …

North Korean Hackers Unveils New MoonPeak Malware With Updated Attack Methods

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Talos has uncovered a new remote access trojan (RAT) family, which is XenoRAT-based malware that is under active development by a North Korean nexus cluster named “UAT-5394.”  While the …

Netflix Security Breach, Hackers Leaked Upcoming Episodes Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have leaked footage and clips from several unreleased Netflix anime shows, including full episodes, online. The content was stolen from one of Netflix’s post-production partners, causing a stir in …

FAA Proposed New Cybersecurity Rules for Airplanes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Aviation Administration (FAA) has proposed new cybersecurity regulations for transport category airplanes, engines, and propellers. This initiative aims to address the growing threats posed by unauthorized electronic interactions, …

GitHub Enterprise Server Vulnerability Allow Attackers to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest update to GitHub Enterprise Server, version 3.13.3, addressed a critical vulnerability (CVE-2024-6800), allowing attackers to forge SAML responses and gain unauthorized access. Enterprise Server 3.13.3 introduces several enhancements …

Russia Reports DDoS Attack Disrupting Telegram and WhatsApp

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian users of popular messaging apps Telegram and WhatsApp experienced significant disruptions, which were attributed to a distributed denial-of-service (DDoS) attack. The state communications monitoring service confirmed the incident, stating …

Zero-Day Vulnerability In Arcadyan WiFi Devices Allows RCE for Root Access – Exploit Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability has been identified in the Arcadyan FMIMG51AX000J model and potentially other devices affiliated with the WiFi Alliance. This flaw allows remote attackers to execute arbitrary code. …

Microsoft Copilot Studio Vulnerability Exploited to Access Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched a critical vulnerability in its Copilot Studio tool that allowed researchers to access sensitive internal cloud data and services. The flaw tracked as CVE-2024-38206, was discovered by …

SolarWinds Web Help Desk RCE Vulnerability Allows Remote Exploitation – Hotfix Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds has released a critical hotfix addressing multiple vulnerabilities in its Web Help Desk (WHD) software. This update is crucial for all users to ensure the security and functionality of …